🕵️ Chapter 13 — Intrusion Detection System (IDS) Cheat Sheet
🗺️ Big Picture
Who attacks? → Intruder Classes & Skill Levels
How do they attack? → Attack Lifecycle (6 phases)
How do we detect? → IDS Types + Detection Approaches
Where do we deploy? → Sensor Placement
What tools? → SNORT Rules + Honeypots
How do we measure? → FP / FN Evaluation
1. Classes of Intruders
Class
Motivation
Methods
Skill
Cyber Criminals
Financial gain
Identity theft, credential theft, ransomware, data theft
Persistent = long-duration attack, stays hidden for months/years
Examples: government-sponsored groups from China, USA, UK, and allies
2. Intruder Skill Levels
Level
Skills
Who?
Apprentice (Script-kiddie)
Uses existing attack toolkits only; doesn't understand how tools work
Largest group; criminals, activists
Journeyman
Modifies/extends toolkits; uses newly found vulnerabilities; can adapt tools for others
All intruder classes
Master
Discovers brand-new vulnerability categories; writes new toolkits from scratch
State-sponsored, elite hackers
🍔 Analogy: Apprentice = orders off the menu. Journeyman = tweaks the recipe. Master = invents the dish from scratch.
Easiest to defend against: Apprentice (uses known tools → known signatures) Hardest to defend against: Master (zero-day discoveries, custom tools)
3. Attack Lifecycle (Intruder Behavior)
① Target Acquisition & Info Gathering
↓
② Initial Access
↓
③ Privilege Escalation
↓
④ Information Gathering / System Exploit
↓
⑤ Maintaining Access
↓
⑥ Covering Tracks
Each Phase in Detail
Phase
What the attacker does
① Recon
Explore corporate website, use dig/host/WHOIS/NMAP, send query emails to fingerprint mail server/OS
② Initial Access
Brute force CMS passwords, exploit vulnerable plugin, send spear-phishing emails with exploit links
③ Privilege Escalation
Scan for local exploits, install sniffers to capture admin passwords, use captured creds for higher access (Guest → Admin)
④ Exploit
Scan files for sensitive data, transfer large document batches to external server, reuse captured passwords across other servers
⑤ Maintain Access
Install remote admin tool / rootkit with backdoor, disable or modify AV / IDS
⑥ Cover Tracks
Use rootkit to hide files, edit log files to erase intrusion entries
Core assumption: An intruder's behavior differs from a legitimate user's in detectable ways.
But there's always overlap between intruder and user profiles → causes:
False Positives — normal behavior flagged as suspicious
False Negatives — actual attack not detected
Three Logical Components of IDS
[Sensors] → collect data (traffic, system calls, logs)
↓
[Analyzers] → determine if intrusion occurred
↓
[User Interface] → view output / control system
6. IDS Types
Type
What it monitors
Data Sources
HIDS (Host-based)
A single host / server
System calls, audit logs, file integrity checksums, registry access
NIDS (Network-based)
Network traffic (packet-by-packet)
Network/transport/application layer packets
Distributed / Hybrid
Multiple hosts + network (centrally correlated)
Host agents + LAN monitor agents → Central Manager
📷 Analogy:
HIDS = CCTV inside a room (watching one host)
NIDS = CCTV at the corridor junction (watching all traffic passing)
Distributed = both cameras + a security room that correlates all footage
7. Why IDS Matters (3 Reasons)
Detect + eject intruders quickly before damage occurs
Builds a baseline of normal user/system behavior over time
Flags significant deviations from baseline
Can detect: zero-day attacks, insider threats, unknown malware
💳 Analogy: Like a bank that knows your spending habits. If your card suddenly gets used overseas at 3 AM → auto-blocked. It doesn't need to know the exact fraud type — it just knows it's unusual.
Sub-approaches:
Sub-approach
How it works
Example
Statistical
Univariate, multivariate, or time-series models of normal metrics
John always logs in 9–5; login at 2 AM → flag
Knowledge-based
Expert rules model what legitimate behavior looks like
Rule: admin should never run rm -rf /interactively
Machine Learning
Trains a model on labeled data to classify normal vs. abnormal
Can also predict, not just classify (threat intelligence)
Anomaly Detection Example:
IDS learns: john logs in 9am–5pm, uses vim/firefox, never touches /etc/passwd
→ Suddenly: john runs bash → sudo cp /etc/shadow /tmp/
→ IDS flags: unexpected sudo + outside normal hours + sensitive file access 🚨
Real-World Tools
Tool
Type
Notes
Wazuh / OSSEC
HIDS
Login, command, file access anomalies
Snort + ML module
NIDS
Abnormal packet patterns (DoS, C2 beaconing)
Zeek (formerly Bro)
NIDS
DNS, HTTP, SSH behavior anomalies
Security Onion
Hybrid
Logs + PCAPs + ML anomaly detection
Suricata + Unsupervised ML
NIDS
Flow features (packet size, timing) for unknown malware
Approach 2 — Signature / Heuristic Detection
Matches known malicious patterns against traffic or system data
Must be specific enough to minimize false alarms
Widely used in anti-virus, traffic proxies, NIDS
Rule-Based Heuristic
Uses rules based on known exploits or known weaknesses
Can also flag suspicious behavior within normal patterns
SNORT = prime example
🛡️ Analogy: Like a spam filter — it knows what spam patterns look like. But it cannot detect brand-new spam it's never seen before.
Anomaly vs. Signature — Comparison
Signature Detection
Anomaly Detection
Pros
Simple, fast, low overhead
Adaptive, detects unknown attacks (zero-day)
Cons
❌ Cannot detect new/unknown patterns
Slower, higher overhead (needs training/baseline)
Best for
Known attack types, policy violations
DoS, scanning, worms, insider threats
📌 If forced to choose between FP and FN for IDS: prefer False Positive — better to flag a normal event for review than to miss a real attack.
10. Evaluation of IDS — FP & FN
Type
Name
What happens
Consequence
False Positive
"Not but In" (normal flagged as attack)
IDS alerts on legitimate activity
Wastes analyst time; alert fatigue
False Negative
"Yes but Out" (attack not detected)
IDS misses real malicious activity
Attack succeeds undetected ⚠️
✈️ Airport Analogy:
False Positive = pulling an innocent passenger aside for screening
False Negative = letting someone with a weapon walk through
Goal: minimize both FP and FN — but FN is more dangerous
11. IDS Placement — Before or After Firewall?
Position
Pros
Cons
After firewall
Less noise (FW already filters obvious threats); lower IDS processing load; focuses on real threats
Misses attacks that firewall lets through
Before firewall
Full visibility of all raw inbound traffic; better for ML training (more data)
Background process on each host; collects security events; transmits to central manager
LAN Monitor Agent Module
Analyzes LAN traffic; reports to central manager
Central Manager Module
Receives all reports; processes and correlates across sources to detect intrusions
Agent Flow:
OS Audit Function
↓
Filter for Security-Relevant Events
↓
Reformat → Host Audit Record (HAR)
↓
Logic Module ←→ Templates
↓
Analysis Module ←→ Central Manager
↓ (Alerts sent up)
14. Network-Based IDS (NIDS)
Monitors traffic at selected network points, packet by packet, in real/near-real time
Examines: network / transport / application layer protocols